Junglewise Threat Intelligence

CVE-2023-37580: Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

CVE-2023-37580 · Severity: critical · CVSS 6.1 · Exploited in the wild · Published 2023-07-27

Technologies: Synacor Zimbra Collaboration Suite (ZCS). Vendors: Synacor.

Executive brief

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability in the Zimbra Classic Web Client. The flaw allows remote attackers to impact the confidentiality and integrity of data via improper neutralization of input during web page generation.

Affected products

  • Synacor Zimbra Collaboration Suite (ZCS) 8 before 8.8.15 Patch 41

Timeline

  • 2023-07-27: disclosed: Date added to CISA KEV catalog
  • 2023-07-27: kev added
  • 2023-07-27: advisory
  • 2023-07-27: exploited: Reported as exploited in the wild per CISA KEV inclusion.

Related threats